CVE Vulnerabilities

CVE-2007-2438

Published: May 02, 2007 | Modified: Oct 16, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.6 HIGH
AV:N/AC:H/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

The sandbox for vim allows dangerous functions such as (1) writefile, (2) feedkeys, and (3) system, which might allow user-assisted attackers to execute shell commands and write files via modelines.

Affected Software

Name Vendor Start Version End Version
Foresight_linux Foresight_linux 1.1 (including) 1.1 (including)
Red Hat Enterprise Linux 5 RedHat vim-2:7.0.109-3.el5.3 *
Vim Ubuntu edgy *
Vim Ubuntu feisty *

References